
CVE-2021-34462 is a great reminder that not every Windows privilege escalation starts with memory corruption. The vulnerability resides in AppXSvc, the service responsible for deploying Microsoft Store applications. During an application reset (e.g., Microsoft Solitaire Collection), AppXSvc recreates user-owned directories and applies security descriptors while running as NT AUTHORITY\SYSTEM. The flaw is a logic error: low-privileged users can modify the DACL of newly created directories during this window, influencing privileged file operations and ultimately achieving SYSTEM privileges. What makes this research particularly interesting is that the exploit relies on understanding AppXSvc internals, Windows ACLs, security descriptors, impersonation, NTFS reparse points, and symbolic link abuse, not a buffer overflow or use-after-free. It's an excellent example of how subtle mistakes in privileged file-system operations can be just as dangerous as classic memory corruption bugs.
Post summary
The commentary discloses a NSA‑software privilege‑escalation flaw in Windows AppXSvc, detailing the logic error that allows low‑privileged users to modify DACLs during directory recreation foreach elevating to SYSTEM, while omitting PoC, exploit code, or patch information.
